Live data from Hacker News

Apple Adds Two-Step Verification to iCloud and Apple ID

appleid.apple.com

21–30 of 51 posts

Re: Apple Adds Two-Step Verification to iCloud and Apple ID

#21

There is nothing on two-factor in my UI. Perhaps it's limited to some geographies? (I'm not in the US)

There's nothing either for me. And I'm in the US, in the heart of Manhattan, using my Time Warner cable. Nothing on the linked page, nothing in my account settings... so I have no idea how this works. EDIT: never mind, it's completely hidden behind "Password and Security" in your account, and then you have to answer your security questions to even SEE what things you can do. ARGH. It took me several tries -- security…

I had the same problem. The questions are general enough (where were you on 1/1/2000?) that I had to try several times to get the right answers.

Re: Apple Adds Two-Step Verification to iCloud and Apple ID

#22
post #12

Apple has done a great job walking users through this process. Setting up "trusted devices" (iPhone, iPad, etc.) works really well: Apple already knows which devices you own, so all you have to do is select the device and you get an instant push notification to unlock to see the verification code. Apple gives you a backup recovery code with very clear instructions to print/write it somewhere safe. They require you to…

Why do you find this more friendly than Google Authenticator? Just because it pushes rather than requiring the user to open an app? Can you still manually get a code, in case you lack network (& don't want to break out the backup code)?

What if you're actually logging in with the iDevice, does it just automatically allow it without asking?

Re: Apple Adds Two-Step Verification to iCloud and Apple ID

#23
post #20
post #11

To what extend is it two factor when one of the factors is the device you are working on? One of the biggest risks I see with iCloud is someone finding/stealing my phone, and using it to erase other devices. A code send to my phone won't prevent that. For online services, a code to your phone makes lots of sense (something you have part). For phone services, I'm less sure.

To use the code sent to the phone, you need to know the password or the recovery key as well. That's the two factor part. Contrast to someone getting your phone today... they can easily determine your iCloud account name in Settings, and then send a password reset for it that is delivered to the unprotected Mail app. So for most people, it's certainly more secure.

What happens if you need a password reset with this new two-factor? Wouldn't it still just email you, leaving you with the same problem?

Re: Apple Adds Two-Step Verification to iCloud and Apple ID

#24
post #16
post #12

Apple has done a great job walking users through this process. Setting up "trusted devices" (iPhone, iPad, etc.) works really well: Apple already knows which devices you own, so all you have to do is select the device and you get an instant push notification to unlock to see the verification code. Apple gives you a backup recovery code with very clear instructions to print/write it somewhere safe. They require you to…

I actually found Google Authenticator just as good on the user experience side, with the added benefit of being far more effective.

Google's approach is more unix-y - it lets you shoot yourself in the foot. Requiring you to put your recovery code back in at least forces people to memorize or write it down.

Now, Google does have a good seemingly automated recovery service (you need to share a lot about your account to prove you're you but it works) - I'd rather not have reason to use it, though.

Re: Apple Adds Two-Step Verification to iCloud and Apple ID

#25

Great to see this as finally an option, interesting that there is a 3 day wait to activate it though...just to be certain it is my identity that wants to add it.

I encountered the same. After struggling with the security questions I set new ones. Then, when enabled two-step auth, they tell you you'll never need the security questions again. drat

Re: Apple Adds Two-Step Verification to iCloud and Apple ID

#26
post #20

Earlier quoted context omitted.

To use the code sent to the phone, you need to know the password or the recovery key as well. That's the two factor part. Contrast to someone getting your phone today... they can easily determine your iCloud account name in Settings, and then send a password reset for it that is delivered to the unprotected Mail app. So for most people, it's certainly more secure.

What happens if you need a password reset with this new two-factor? Wouldn't it still just email you, leaving you with the same problem?

No, the FAQ says: You can reset your password at My Apple ID by using your Recovery Key and one of your trusted devices.

I think they do a pretty good job of emphasizing that there are three things involved here: Recovery Key, password, any trusted device. Any two will allow you to recover the third (except if you lose your phone). Not having any two and you lose your ID forever.

Re: Apple Adds Two-Step Verification to iCloud and Apple ID

#27

Earlier quoted context omitted.

The three day wait is only for users that recently modified their account. From http://support.apple.com/kb/HT5570 "As a basic security measure, Apple does not allow two-step verification setup to proceed if any significant changes have recently been made to your account information. Significant changes can include a password reset or new security questions. This waiting period helps Apple ensure that you are the onl…

The process forced me to update my password to use their new password requirements which then forced me to wait 3 days. I'm pretty sure my old password was secure but it didn't meet all of the new standards. Kind of annoying.

I was not prompted to update my password (and had long ago set up security questions), and was able to set up 2-factor immediately.

Re: Apple Adds Two-Step Verification to iCloud and Apple ID

#29
post #20

Earlier quoted context omitted.

To use the code sent to the phone, you need to know the password or the recovery key as well. That's the two factor part. Contrast to someone getting your phone today... they can easily determine your iCloud account name in Settings, and then send a password reset for it that is delivered to the unprotected Mail app. So for most people, it's certainly more secure.

What happens if you need a password reset with this new two-factor? Wouldn't it still just email you, leaving you with the same problem?

[deleted]

Re: Apple Adds Two-Step Verification to iCloud and Apple ID

#30

I just attempted to add two-step, and Apple told me I needed a stronger password before continuing. How do they know my password strength if it is salted+hashed properly?

They could store a strength measurement alongside the salt and hash.
Post reply on HN